Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

Swiss State Secretariat Helps Blockchain Incubator Firm Set Up Base in South Africa
Swiss State Secretariat Helps Blockchain Incubator Firm Set Up Base in South Africa Switzerland’s State Secretariat for Economic Affairs (SECO) is reported
Popular Tezos NFT Marketplace Discontinues Services Without Explanation
Popular Tezos NFT Marketplace Discontinues Services Without Explanation After becoming one of the top non-fungible token (NFT) marketplaces, the Tezos-based NFT market Hic et nunc
Instagram Is ‘Exploring NFTs’ to ‘Make Them More Accessible to a Wider Audience,’ Says CEO
Instagram Is "Exploring NFTs" to "Make Them More Accessible to a Wider Audience," Says CEO According to the CEO of Instagram, Adam Mosseri, the social media application is looking
If Solana Reclaims $210 ‘New Highs Are Next’ – Price Analysis
Este artículo también está disponible en español. The crypto market showed signs of life yesterday after enduring weeks of persistent selling pressure, with many assets s
Kenyan AI and Blockchain Startup Receives Investment From Swiss VC Firm
Kenyan AI and Blockchain Startup Receives Investment From Swiss VC Firm Fastagger Inc, an artificial intelligence and blockchain startup from Kenya, recently revealed that it had r
Bitcoin Miner Hut 8 to Add 275 PH/s of Mining Capacity With $8.3M Capital Raise
Bitcoin Miner Hut 8 to Add 275 PH/s of Mining Capacity With $8.3M Capital RaiseHut 8 Mining Corp. has raised $8.3 million from the sale of 6% of its shares to investors. The Canadia
Dogecoin Activity Levels Crash To 4-Month Lows, Does This Spell Doom For The Meme Coin?
Este artículo también está disponible en español. Crypto analyst Ali Martinezhas revealed a bearish on-chain metric for Dogecoin, sparking a negative outlook for the fore
Nigeria begins review of its blockchain technology policy
Amaka Nwaokocha11 hours agoNigeria begins review of its blockchain technology policyThe steering committee’s work is actively toward Nigeria taking a leadership position in African blockchain development.1198 Total vie
Rebase Token Carnage: OHM, TIME, KLIMA Down More Than 98% From All-Time Highs
Rebase Token Carnage: OHM, TIME, KLIMA Down More Than 98% From All-Time Highs About four months ago, four of the top rebase tokens by market valuation were worth close to $8 billio
Bitcoiner Elected to US Senate: Cynthia Lummis Sees ‘Great Promise’ in Bitcoin
Bitcoiner Elected to US Senate: Cynthia Lummis Sees "Great Promise" in Bitcoin A bitcoin hodler has won a U.S. Senate seat. Cynthia Lummis is a bitcoin owner who
Balaji Srinivasan Says Hyperinflation Happening Now — Makes Million-Dollar Bets on Bitcoin Price Exceeding $1M in 90 Days
Balaji Srinivasan Says Hyperinflation Happening Now — Makes Million-Dollar Bets on Bitcoin Price Exceeding $1M in 90 Days Venture capitalist and angel investor Balaji Srinivasan
Bitcoin, Ethereum Technical Analysis: ETH Falls Below $2,000 as Crypto Bearish Pressure Intensifies 
Bitcoin, Ethereum Technical Analysis: ETH Falls Below $2,000 as Crypto Bearish Pressure Intensifies  Following several sessions of consolidation, ETH has finally caved in, droppin